From 8dc170b9d9e56d1b7491c429badd7f722bb27987 Mon Sep 17 00:00:00 2001 From: Dalton Hubble Date: Mon, 8 Jun 2020 12:37:09 -0700 Subject: [PATCH] Update security disclosure contact email * Use security@psdn.io across github.com/poseidon projects --- docs/advanced/customization.md | 2 +- docs/topics/security.md | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/advanced/customization.md b/docs/advanced/customization.md index 2001a59b..c92d1adb 100644 --- a/docs/advanced/customization.md +++ b/docs/advanced/customization.md @@ -176,7 +176,7 @@ To customize low-level Kubernetes control plane bootstrapping, see the [poseidon ## Kubelet -Typhoon publishes Kubelet [container images](/topics/security.md#container-images) to Quay.io (default) and to Dockerhub (in case of a Quay [outage](https://github.com/poseidon/typhoon/issues/735) or breach). Quay automated builds also provide the option for fully verifiable tagged images (`build-{short_sha}`). +Typhoon publishes Kubelet [container images](/topics/security/#container-images) to Quay.io (default) and to Dockerhub (in case of a Quay [outage](https://github.com/poseidon/typhoon/issues/735) or breach). Quay automated builds also provide the option for fully verifiable tagged images (`build-{short_sha}`). To set an alternative Kubelet image, use a snippet to set a systemd dropin. diff --git a/docs/topics/security.md b/docs/topics/security.md index 78e5f4fb..e793c7a0 100644 --- a/docs/topics/security.md +++ b/docs/topics/security.md @@ -64,9 +64,9 @@ Two tag styles indicate the build strategy used. * Typhoon internal infra publishes single and multi-arch images (e.g. `v1.18.3`, `v1.18.3-amd64`, `v1.18.3-arm64`, `v1.18.3-2-g23228e6-amd64`, `v1.18.3-2-g23228e6-arm64`) * Quay and Dockerhub automated builds publish verifiable images (e.g. `build-SHA` on Quay, `build-TAG` on Dockerhub) -The Typhoon-built Kubelet image is used as the official image. Automated builds provide an alternative image for those preferring to trust images built by Quay/Dockerhub (albeit lacking multi-arch). To use the fallback registry or an alternative tag, see [customization](/advanced/customization.md#kubelet). +The Typhoon-built Kubelet image is used as the official image. Automated builds provide an alternative image for those preferring to trust images built by Quay/Dockerhub (albeit lacking multi-arch). To use the fallback registry or an alternative tag, see [customization](/advanced/customization/#kubelet). ## Disclosures -If you find security issues, please email dghubble at gmail. If the issue lies in upstream Kubernetes, please inform upstream Kubernetes as well. +If you find security issues, please email `security@psdn.io`. If the issue lies in upstream Kubernetes, please inform upstream Kubernetes as well.